Hunt Windows

Local Windows privilege escalation on a STANDALONE / workgroup host, or a local shell on a domain member - foothold to SYSTEM. Token privileges (SeImpersonate/Potato), service misconfig (weak perms / unquoted path / writable binary), registry autologon creds, scheduled-task + writable-script abuse, DLL hijack, AlwaysInstallElevated, UAC bypass, credential loot. For DOMAIN escalation (kerberoast/DCSync/ADCS/BloodHound) use hunt-ad instead. Wiki-first, FIND schema output.

Encod3d-Sec Updated

File contents

Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-windows commit c751791c97

Frequently asked questions

npx skillmds@latest add encod3d-sec/hunt-windows